Drupal Project Issue Tracking Module Multiple Input Validation Vulnerabilities
BID:27545
Info
Drupal Project Issue Tracking Module Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 27545 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2008 12:00AM |
| Updated: | Jan 31 2008 08:57PM |
| Credit: | Chad Phillips and Derek Wright are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Drupal Project issue tracking 4.7 2.2 Drupal Project issue tracking 4.7 1.2 Drupal Project issue tracking 5.x-2.x Drupal Project issue tracking 5.0-1.0 Drupal Project issue tracking 4.7.x-2.x Drupal Project issue tracking 4.7.x-1.x Drupal Project issue tracking 4.7.0-2.4 Drupal Project issue tracking 4.7.0-2.3 Drupal Project issue tracking 4.7.0-2.1 Drupal Project issue tracking 4.7.0-2.0 Drupal Project issue tracking 4.7.0-1.4 Drupal Project issue tracking 4.7.0-1.3 Drupal Project issue tracking 4.7.0-1.1 Drupal Project issue tracking 4.7.0-1.0 |
| Not Vulnerable: |
Drupal Project issue tracking 5.x-2.0 Drupal Project issue tracking 5.x-1.3 Drupal Project issue tracking 4.7.x-2.7 Drupal Project issue tracking 4.7.x-1.7 |
Discussion
Drupal Project Issue Tracking Module Multiple Input Validation Vulnerabilities
The Project Issue Tracking module for Drupal is prone to multiple input-validation vulnerabilities because it fails to adequately sanitize user-supplied input. These issues include a cross-site scripting vulnerability as well as a vulnerability that allows attacker to upload arbitrary code.
Successfully exploiting these issues can allow an attacker to upload and execute arbitrary code in the context of the application. This may help the attacker steal cookie-based authentication credentials, and launch additional attacks.
Note that Drupal Core without this module is not affected by these issues.
The Project Issue Tracking module for Drupal is prone to multiple input-validation vulnerabilities because it fails to adequately sanitize user-supplied input. These issues include a cross-site scripting vulnerability as well as a vulnerability that allows attacker to upload arbitrary code.
Successfully exploiting these issues can allow an attacker to upload and execute arbitrary code in the context of the application. This may help the attacker steal cookie-based authentication credentials, and launch additional attacks.
Note that Drupal Core without this module is not affected by these issues.
Exploit / POC
Drupal Project Issue Tracking Module Multiple Input Validation Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
Drupal Project Issue Tracking Module Multiple Input Validation Vulnerabilities
Solution:
The vendor has released updates that address these issues. Please see the references for more information.
Drupal Project issue tracking 4.7.0-1.0
Drupal Project issue tracking 4.7.x-1.x
Drupal Project issue tracking 4.7.0-1.4
Drupal Project issue tracking 4.7.0-1.3
Drupal Project issue tracking 4.7.0-2.1
Drupal Project issue tracking 4.7.0-1.1
Drupal Project issue tracking 4.7.0-2.0
Drupal Project issue tracking 4.7.0-2.4
Drupal Project issue tracking 5.x-2.x
Drupal Project issue tracking 5.0-1.0
Drupal Project issue tracking 4.7.0-2.3
Drupal Project issue tracking 4.7.x-2.x
Drupal Project issue tracking 4.7 1.2
Drupal Project issue tracking 4.7 2.2
Solution:
The vendor has released updates that address these issues. Please see the references for more information.
Drupal Project issue tracking 4.7.0-1.0
-
Drupal project_issue-4.7.x-1.7.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-1.7.tar.gz
Drupal Project issue tracking 4.7.x-1.x
-
Drupal project_issue-4.7.x-1.7.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-1.7.tar.gz
Drupal Project issue tracking 4.7.0-1.4
-
Drupal project_issue-4.7.x-1.7.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-1.7.tar.gz
Drupal Project issue tracking 4.7.0-1.3
-
Drupal project_issue-4.7.x-1.7.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-1.7.tar.gz
Drupal Project issue tracking 4.7.0-2.1
-
Drupal project_issue-4.7.x-2.7.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-2.7.tar.gz
Drupal Project issue tracking 4.7.0-1.1
-
Drupal project_issue-4.7.x-1.7.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-1.7.tar.gz
Drupal Project issue tracking 4.7.0-2.0
-
Drupal project_issue-4.7.x-2.7.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-2.7.tar.gz
Drupal Project issue tracking 4.7.0-2.4
-
Drupal project_issue-4.7.x-2.7.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-2.7.tar.gz
Drupal Project issue tracking 5.x-2.x
-
Drupal project_issue-5.x-2.0.tar.gz
http://ftp.drupal.org/files/projects/project_issue-5.x-2.0.tar.gz
Drupal Project issue tracking 5.0-1.0
-
Drupal project_issue-5.x-1.3.tar.gz
http://ftp.drupal.org/files/projects/project_issue-5.x-1.3.tar.gz
Drupal Project issue tracking 4.7.0-2.3
-
Drupal project_issue-4.7.x-2.7.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-2.7.tar.gz
Drupal Project issue tracking 4.7.x-2.x
-
Drupal project_issue-4.7.x-2.7.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-2.7.tar.gz
Drupal Project issue tracking 4.7 1.2
-
Drupal project_issue-4.7.x-1.7.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-1.7.tar.gz
Drupal Project issue tracking 4.7 2.2
-
Drupal project_issue-4.7.x-2.7.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-2.7.tar.gz
References
Drupal Project Issue Tracking Module Multiple Input Validation Vulnerabilities
References:
References: